2 min read

Phishing Attacks Increase as Facebook and Microsoft are Most Abused

Phishing Attacks Increase as Facebook and Microsoft are Most Abused

Published 8/1/2022

I. Targeted Entities

  • Microsoft, Facebook, and other large tech brands

II. Introduction

Phishing attacks exploiting the Microsoft and Facebook brands, among others, have increased between 2021 and 2022.

III. Background Information

According to researchers at Vade, Microsoft, Facebook, and the French bank Crédit Agricole are the top abused brands.[1] The report also says that phishing attacks exploiting the Microsoft brand increased 266% in the first quarter of 2022 compared to 2021. Phony Facebook messages are up 177% in the second quarter of 2022, compared to 2021.[1]

The research by Vade analyzed unique phishing URLs used by threat actors, not the number of phishing emails associated with those URLs. Their report listed the 25 most commonly phished companies, the most targeted industries, and the days of the week for phishing emails.[1] Other brands at the top of the list include Crédit Agricole, WhatsApp, and French telecommunications company Orange. PayPal, Google, and Apple also made the list.[1]

The report by Vade found that during the first half of 2022, 34% of all unique phishing attacks tracked by the researchers at Vade impersonated financial services brands. The next most popular sector was cloud service providers, with Microsoft, Google, and Adobe being prime targets. The social media sector was also popular, with Facebook, WhatsApp, and Instagram among the brands exploited in the attacks.[1] The researchers also found that the most popular days for sending phishing emails were Monday through Wednesday. The weekend saw few phishing emails, with only 20% sent.[1]

IV. MITRE ATT&CK

  • T1566 – Phishing
    Adversaries will send phishing messages to gain access to a victim’s machine. These phishing attempts may come via a link or an attachment, and typically execute malicious code on victim machines.

V. Recommendations

  • Phishing Awareness Training
    Users should be informed and educated about new kinds of phishing scams currently being used and those that have been used in the past. Awareness training should instruct users to avoid suspicious emails, links, websites, attachments, etc. Users should also be educated about new types of attacks and schemes to mitigate risk. Recommended link: https://www.us-cert.gov/ncas/tips/ST04-014
  • Set Antivirus Programs to Conduct Regular Scans
    Ensure that antivirus and antimalware programs are scanning assets using up-to-date signatures.
  • Strong Cyber Hygiene
    Enforce a strong password policy across all networks and subsystems. Remind users to be wary of any messages asking for immediate attention, links, downloads, etc. All sources should be verified. Recommended link: https://us-cert.cisa.gov/ncas/alerts/aa21-131a
  • Turn on Endpoint Protection
    Enable endpoint detection and response (EDR) to stop unknown malware in the product you’re using.
  • Malware Monitoring
    Continuously monitor current and new types of malware. Stay up to date on intel and advancements to prevent, defend, and mitigate these types of threats.

VI. Indicators of Compromise (IOCs)

This threat advisory contains no indicators of compromise, but readers are advised to be aware of the links and attachments they receive to ensure their safety.

VII. References

(1) Nelson, Nate. “Phishing Attacks Skyrocket with Microsoft and Facebook as Most Abused Brands.” Threatpost English Global, July 26, 2022. https://threatpost.com/popular-bait-in-phishing-attacks/180281/.

(2) Petitto, Natalie. “Phishers’ Favorites Top 25, H1 2022: Microsoft Is the Most Impersonated Brand in Phishing Attacks.” Vade, July 26, 2022. https://www.vadesecure.com/en/blog/phishers-favorites-top-25-h1-2022.

Contributing Security Analysts: Dorian Pope, Sreten Dedic, EJ Bulut, and Tural Hagverdiyev

Other posts of interest...

Phishers Spoof 2FA in Coinbase Accounts Stealing

1 min read

Phishers Spoof 2FA in Coinbase Accounts Stealing

Originally published 8/16/2022 I. Targeted Entities Coinbase accounts II. Introduction Attackers are bypassing two-factor authentication (2FA) and...

Read More
Microsoft Releases Workaround for Zero-Day Flaw

1 min read

Microsoft Releases Workaround for Zero-Day Flaw

Originally published: 06/16/2022 I. Targeted Entities Microsoft Office users II. Introduction Microsoft has recently established a workaround for a...

Read More
REvil is Back and Executes DDoS Attacks

1 min read

REvil is Back and Executes DDoS Attacks

Originally published 06/06/2022 I. Targeted Entities Akami Technologies Incorporated and customers II. Introduction A recent denial-of-service...

Read More